PuppyIP Resource Center
AI Development & Automation 9 min read Published 2026-09-30 Updated 2026-10-08

OpenAI Agents API Computer Use: US Residency and Permission Boundaries

Agents API can create hosted browser sessions, but first check its data conditions: the current beta supports US residency only and does not support Zero Data Retention (ZDR), including self-hosted sandboxes. Once these conditions fit the project, address website-origin approvals, authentication, and result verification.

OpenAI Agents API Computer Use Browser agents Website authorization Data residency ZDR

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • The current Agents API beta supports US residency only, without ZDR. Hosting the sandbox on your own server does not remove that restriction.
  • A browser task starts with an Agents API session. Add computer_use to agent.tools and enable desktop in the openai_hosted environment. Creating a session alone does not execute a task.
  • The application must track session events. Users review and approve, deny, or cancel new website origins. Enabling network access does not authorize every website or account action.
  • Handle login in the application's interface. Verify the main agent's result against browser activity, recover the original session after disconnection, and delete the session when finished.
  • The public announcement offers the developer beta without an extra API platform fee; tokens and tools are still billed. Verify computer-use permissions, actual costs, and website authentication per project.

Before integration, check where data may reside

OpenAI's current Agents API beta FAQ explicitly supports US data residency only and does not support Zero Data Retention (ZDR), including when using a self-hosted sandbox.

Self-hosting lets your application manage its runtime and lifecycle; it does not automatically change Agents API data controls. Hypothetical example: an EU-only residency requirement is not satisfied merely by self-hosting. Verify the interface's conditions before submitting project data.

Separate September 29's addition from the original Agents API

OpenAI introduced the Agents API public beta on September 10 with managed agent sessions, tools, and environments. The September 29 DevDay recap added computer use to Agents API, alongside multi-agent support, tool search, tool calls, and context compaction.

This guide focuses on whether developers can integrate the hosted browser workflow. DevDay's date is not the Agents API's original launch date.

The official recap describes API availability alongside Pro 500 and Enterprise access in Codex and ChatGPT Work. A ChatGPT plan does not automatically authorize an API project key, nor establish access to every website or account.

Agents API, Agents SDK, and Responses API are separate integration surfaces. Implement these session and event steps from the Agents API computer-use guide rather than copying older Responses computer-use examples.

Step 1: Verify the key, tool, and hosted browser configuration

Complete the official Agents API quickstart prerequisites for an API key and SDK, and confirm that your project can create beta Agents API sessions.

The computer-use guide requires a computer_use tool in agent.tools and an openai_hosted environment with desktop.enabled set to true. Its example also enables network access. The example model is gpt-6-astra; that does not guarantee every project's model access or billing tier.

Create the session with client.beta.agents.sessions.create, or follow the documented POST /v1/agents/sessions request with OpenAI-Beta: agents=v1. Save its session ID, creation result, and actual configuration.

Creation assigns no task and approves no website origin. If creation fails or the result is unclear, check project status and logs before creating additional sessions without evidence.

Step 2: Send the task and handle every origin approval

After sending a task to the created session, keep reading its event stream. On agent.session.requires_action, fetch current required_actions, inspect the computer_use_approval_request request_id, request type, target origin, and reason, then show the origin to the user.

Only after user confirmation should the application return approve, deny, or cancel for browser_origin_access through that session's events interface. network.access=enabled does not mean the target website is approved.

For authenticated sites, handle browser_authentication in a separate application interface where the user selects a login method and enters credentials. Do not put passwords, verification codes, or session cookies into agent instructions or article examples. The guide says passkeys and QR-code login are currently unsupported, and only the main agent can request browser authentication. Acceptance of an approval event does not establish completed navigation or task execution; continue checking session events.

Step 3: Verify, recover the same session, and clean up

When the main agent's turn completes, verify its output, the target page state, and necessary browser activity records. Screenshots can help, but one screenshot does not prove a business-system write or payment succeeded. After disconnection, recover the same session and inspect its current events and result before creating another session that could repeat side effects.

Review saved browser activity and delete sessions no longer needed following the official guide. Use restricted test accounts and controlled sites, recording session IDs, approvals, results, and failure stages without credentials or customer-sensitive data. This guide is based on public documentation; it does not claim a real operation completed through PuppyIP or any particular account.

Origin approval is separate from sensitive-action confirmation

The documentation says approving a website origin does not guarantee another prompt before every action there. If purchases, deletions, or other irreversible actions require individual confirmation, restrict the hosted browser to resources unable to perform those actions, or use a browser runtime you control that enforces confirmation. Website content and tool returns are untrusted input: they cannot grant permissions or override user instructions.

Before integration, list allowed origins, account roles, permitted actions, and steps requiring human confirmation. Start with public read-only tasks, then expand gradually. Stop subsequent actions if approvals cannot be verified, login fails, page states conflict, or the main agent has not finished. Keep non-sensitive evidence. A proxy, egress IP, or connectivity does not replace website authorization or business-action confirmation.

Check pricing and availability for the actual project

OpenAI's September 10 announcement offers the Agents API public beta to developers without an extra platform fee, while billing tokens and tool usage. The September 29 computer-use announcement and guide do not establish a separate fixed price, project quota, or login availability for every website.

Set budgets from current official prices and actual project usage. No additional platform fee does not mean free browser execution.

For integrating a hosted browser into your own application, verify the Agents API session workflow. For personal use of similar capabilities in Codex or ChatGPT Work, check that product and plan's availability first. Model support, regions, organization policies, and account status may differ. For 403 responses, missing tools, or absent approvals, distinguish project permissions, session configuration, and website restrictions; changing network egress alone is not a solution.

Sources

Frequently Asked Questions

Do US-only residency and no ZDR apply to all OpenAI APIs?

This verification concerns Agents API beta, not Responses API, Agents SDK, or every OpenAI product. Check each surface's data controls separately; another API's entitlements also cannot be assumed for Agents API sessions.

Does creating a browser session immediately run the task?

No. The guide creates and saves the session ID first, then sends tasks through session events, handles origin and authentication approvals, and checks the result.

Does network.access enable direct access to every site?

No. The guide requires user approval before accessing each new website origin; the application must handle the associated required_actions.

Does origin approval guarantee confirmation before every purchase?

No. It does not enforce individual confirmation for every action. Restrict browser resources or use a controlled runtime that enforces confirmation for purchases, deletions, and similar actions.

Should I give the agent my login password directly?

No. Handle login in a separate application interface where the user enters credentials. The current official flow does not support passkeys or QR-code login.

Does public beta mean computer use is free or available to every account?

No. Agents API has no extra platform fee, but tokens and tools are billed. Public documentation does not establish a project's model permission, quota, actual costs, or website-account login access.